Regulatory compliance for financial services

Regulatory requirements are growing more complex as expectations rise. Wipfli helps financial services organizations improve compliance, mitigate risk and support operational effectiveness.

How we help you

From new technologies to new generations of customers, financial services organizations are facing a variety of ways they can increase efficiency and grow. But as the industry changes, so do regulatory requirements and expectations.

Strengthen compliance audit and monitoring.

Mitigate fair lending risks.

Get comprehensive support for BSA/ AML.

Access compliance specialists and resources on demand.

Simplify your compliance

Resource-intensive processes and evolving regulatory priorities make compliance more challenging than ever. Let Wipfli’s regulatory risk and compliance team help with our risk-based solutions, real-world best practices and responsive support.

Explore our regulatory compliance services for the financial services industry

Insights and resources

  • Smiling faces

    ARTICLE

    Participation loans: protect your position

    Participation loans for financial institutions offer a way to generate commercial lending income without creating a new borrower relationship from scratch. But acting as the participant in these loans comes with risks. Financial institution CEOs and CLOs need to be sure safeguards are in place to avoid ending up on the wrong side of a regulatory exam and to reduce the risk of losing money on a participant loan. Keep reading to learn about three actions participants should take to protect themselves. What is a participation loan? Financial institutions operate under legal lending limits that cap how much they can lend to any single borrower. Many also maintain internal lending limits that sit below the legal threshold. When a commercial borrower needs more money than one institution can lend, or more than it is comfortable lending due to other risks such as collateral concentrations, the initial institution can bring in another institution to share the loan. This is a participation loan. The originator of the loan is the lead. The institution brought on board to carry the remaining portion of the loan is the participant. In some cases, there may be more than one participant. The lead manages the borrower relationship and services the debt. The participant purchases a percentage of the loan and receives a proportionate share of payments and absorbs a proportionate share of any loss. If your institution owns 50% of the participation, 50% of the payments come to you. And if there’s a loss, you will absorb 50% of that as well. These arrangements allow credit unions to deploy capital for commercial lending without having to establish new relationships with borrowers. But there are risks the participants need to be aware of. Participation lending is available only for commercial loans, not for consumer lending or residential mortgages. These are business loans to commercial borrowers that can be complex. Three things every participant institution must do If your financial institution is considering being a participant in a loan, here are three actions that will help mitigate the risks of losing money and of regulatory violations: 1. Conduct an independent credit evaluation When you agree to be a participant, the lead institution sends you their underwriting file, which should include financial statements, borrower background, collateral analysis and its risk conclusions. That information is a good starting point, but you need to do your own evaluation. Independent credit evaluation for loan participation means applying your institution’s established credit policies to the borrower, as if they had approached you directly for a loan. You can’t simply review the lead’s package and mark it as approved. That’s not an independent evaluation. Regulators have become increasingly direct on this point. Institutions that can’t show their own analysis that’s independent of the lead’s underwriting are creating meaningful examination exposure. Be prepared to answer these questions: What did your credit analysis independently conclude? How did you apply your own underwriting criteria? Where’s your work? Simply put, if the participation opportunity doesn’t meet your standards for a loan someone applied for at your institution, you should pass. 2. Negotiate a clear participation agreement The participation agreement is the contract that establishes the roles and responsibilities for the lead and participant institutions. Treating it as a formality is a mistake. Dedicate time to negotiating terms that protect your interests. Don’t make the mistake of assuming the lead’s standard form covers everything you need. A well-structured agreement for a participation loan should define: The lead institution’s responsibilities for obtaining updated borrower information. Specific timelines for delivering that information to the participant. How loan payments are received and remitted, including any netting arrangements. Interest income based on ownership percentage. How problem credits are managed and who makes decisions. Actions the lead can take unilaterally vs. those requiring participant consent. The absence of clear terms can leave participant financial institutions without the information they need to properly monitor the loan and have no contractual leverage to demand it. Negotiate the agreement before you sign it, not after something goes wrong. 3. Keep your books current As the participant, ongoing monitoring of the loan is your responsibility. You can’t just forget about it and assume the lead will tell you if something changes. Each year, participants should complete a formal internal evaluation that includes reviewing current borrower information, updating the risk rating and assessing whether the borrower remains capable of servicing the debt. The evaluation must be based on current data. The lead institution needs to provide you with updated information. Your agreement should define when that information is due, and you should hold the lead on it. Don’t assume that because the lead hasn’t raised a concern, there aren’t any. You must do your own analysis. When doing your annual review, the key information to gather, assess and document includes: Current financial statements or business tax returns for operating companies. Rent rolls, lease schedules and operating statements for non-owner-occupied commercial real estate. Evidence of consistent cash flow sufficient to service debt over at least the next 12 months. Any material changes to the borrower’s business, ownership or collateral position. Read more How financial institutions can verify their CECL compliance Avoiding adjustable-rate mortgage loan compliance challenges Regulation E error resolution misconceptions and common errors

  • Business people with shining tablet talking in office.

    ARTICLE

    Cybersecurity risks in the banking industry: Threats and defenses

    Explore the biggest cybersecurity risks in the banking industry, from phishing and ransomware to third-party risk, and learn which defenses financial institutions should prioritize.

  • Teamwork in Technology Laboratory.

    ARTICLE

    Is hiring a vCISO the most cost-effective way for financial institutions to mitigate cybersecurity risks?

    While financial institutions have long needed to guard against cybersecurity threats, today’s threat environment grows ever more complex. AI has created a wave of new dangers — not just in the hands of attackers, but also when used by your own team ­— while longstanding risks like phishing scams, ransomware attacks and third-party data breaches remain present. To protect themselves from this web of cybersecurity challenges, more financial institutions are turning to a fractional or virtual chief information security officer (vCISO) as a more cost-effective alternative to a full-time CISO. Could this make sense for your institution as well? Keep reading to learn more. Financial institutions must mitigate cybersecurity risks like phishing, third-party data breaches and AI Financial institutions must manage cybersecurity risks stemming from both external attackers and internal mistakes. Key risk areas include: Business email compromise: During this type of attack, often called a phishing scam, an attacker will attempt to gain unauthorized access to your systems via fraudulent email messages. Ransomware attack: Business email compromise can sometimes lead to a ransomware attack, during which a hacker is able to block you from accessing your core systems or critical data until you pay a ransom. Business continuity disaster recovery: As financial institutions increasingly transition onto cloud-based systems, many have not yet adapted their disaster recovery strategies to adjust to this change. AI risks: Some of the biggest AI-related risks are actually about how your own team uses it , like poor governance or shadow AI use that can lead to your private data being fed into public AI models, with unpredictable consequences. Also watch for SaaS vendors who add AI features into platforms you already use before your IT team can vet them for operational or security risks. Third-party data risks: A data breach at one of your software or IT vendors can expose any data you shared with that vendor — even if your own security remains fully intact. Financial institutions are more likely to suffer from this kind of data breach than experience a successful direct cyberattack. Managing these risks in a proactive, strategic way is beyond the purview of your regular IT team. That’s why some institutions hire a CISO. How does a vCISO help you defend your financial institution from cyberthreats? A vCISO is a C-suite-level fractional executive who leads your cybersecurity and cyber risk management efforts. Your vCISO’s primary responsibility is to mitigate your everyday and strategic risks in areas like data security, technology and AI, while also serving as a bridge between your IT team and your other executives. Look to a vCISO to: Bolster your cybersecurity: A vCISO takes the lead on cybersecurity inside your C-suite. vCISO responsibilities include assessing your current defenses, finding gaps and implementing an up-to-date cybersecurity strategy. Lead AI governance and security efforts: Your vCISO will also take charge of your AI governance and security policies. Good AI governance can help ward off shadow AI risks , reducing the chance that team members unthinkingly share your business or customer data with unauthorized or public AI systems. Manage third-party data security risks: A skilled vCISO will also know how to map out your third-party data risks and assess whether your vendors are taking sufficient steps to secure the data you share with them. Bridge the gap between C-suite and IT: A vCISO serves as a crucial conduit between your executive offices and your frontline IT team, able to speak the language of both groups and advocate for the latter before the former. Now, if a vCISO is such an asset, shouldn’t you just hire a full-time CISO instead? Not always. Why should your financial institution hire a vCISO rather than a full-time CISO? If your financial institution wants stronger cybersecurity but doesn’t have the need (or budget) for a full-time CISO, a vCISO or fractional CISO can deliver the same level of insight, experience and strategic capability for a fraction of the cost. Onboarding a vCISO can also give you a broader perspective on how the financial services industry as a whole is tackling cybersecurity. Key benefits to hiring a vCISO include: Cost-effective security leadership Unless you actually need 40+ hours a week of strategic cybersecurity leadership — and most financial institutions don’t — it may not make sense to pay a mid-six-figure salary plus benefits to a full-time CISO. A vCISO typically costs dramatically less than a full-time hire, while providing the level of support your business requires. Scalable support You can hire a vCISO for two hours a week, or 20. If you’re growing your business, your vCISO support can grow along with it, and you can also choose to engage a vCISO on a per-project or time-limited basis. A vCISO can also go back and forth between providing strategic leadership and taking charge of implementing or executing on individual projects. Regulatory goodwill Financial regulators no longer want to see one IT director managing both your IT and cybersecurity. Hiring a vCISO eliminates this problem and also keeps most cybersecurity matters off your CFO’s or COO’s plate. (Some forward-thinking institutions are doubling down on this approach by hiring a full-time CIO to implement their overall technology strategy and working with a vCISO to manage cybersecurity.) Broad industry awareness An experienced vCISO will typically have worked with dozens of financial institutions. You’ll gain access to that big-picture awareness — which can’t be matched by someone who has worked only as an in-house CISO — to better understand how the financial services industry as a whole is solving cybersecurity challenges. Coaching and leadership development If you have promising in-house IT staff who want more responsibility but lack the strategic skills to take on a CISO role themselves, a vCISO can help prepare them to move up. This allows you to shore up your cybersecurity now while also creating a path forward for your top talent. What is the process for hiring a vCISO? Hiring a vCISO should be a relatively straightforward process. There are three major steps: 1. Find a cybersecurity and risk management advisory firm. 2. Assess your specific needs and develop a cybersecurity roadmap. 3. Onboard a vCISO (typically provided by the advisory firm) to oversee implementing your roadmap. As you consider which cybersecurity advisory firm to hire, make sure that you’ll only be paying for the level of vCISO service that you actually need. Don’t get locked into 15 hours a week of vCISO support if you only need five. Read more Minus a data strategy, financial institutions will fail at AI Financial institutions must be more proactive about general ledger certification Can traditional banking avoid losing Gen Z to fintech?

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

From fair lending and BSA/AML compliance to compliance audits and monitoring, our professionals are ready to help.